QCS Security Advisory Desk

Network vulnerabilities and vendor patches, verified at the source.

Monitor network-edge vulnerabilities, known exploitation, affected products, mitigations, and vendor patch guidance without waiting for a weekly editorial cycle.

QCS pathSource-to-action path
  1. 01Official sourceMonitor vendors and trusted authorities.
  2. 02Verify contextCheck products, exposure, and evidence.
  3. 03Set prioritySeparate urgent action from useful reading.
  4. 04Act or learnPatch, mitigate, investigate, or prepare.

Live intelligence

See the items that can change today's patch or mitigation plan.

Priority combines source severity, known exploitation, remote attack conditions, recency, and network-edge relevance.

Cisco high security advisory
highPriority 100/100

Cisco

ClamAV Vulnerabilities Affecting Cisco Products: August 2026

Multiple security flaws have been found in ClamAV, an antivirus scanning component used by some Cisco software. These flaws could let an attacker send specially crafted files to disrupt the scanning process, causing it to stop working temporarily (a denial of service). Cisco has fixed these flaws in newer software versions for affected products. There are no workarounds to prevent these issues, so updating the software is the best way to stay protected.

CVE-2026-20337CVE-2026-20338CVE-2026-20339CVE-2026-20345
13 Aug 2026Proof-of-concept exploit code is publicly available for CVE-2026-20337 and CVE-2026-20338. There is no information about active malicious exploitation of these vulnerabilities.
Open advisory
Cisco high security advisory
highPriority 100/100

Cisco

Cisco Secure Firewall Management Center Software Static Credential Vulnerability

A security flaw in Cisco Secure Firewall Management Center software lets attackers log in remotely without needing to authenticate, using a built-in low-privileged account. This access can expose sensitive system data. While the account limits access rights, the vulnerability still poses significant risk, especially combined with other flaws that might allow attackers to gain higher privileges. Cisco warns that this threat is serious and recommends updating the software to fix it, as no temporary workarounds exist. Limiting public internet exposure of the management interface can reduce risk.

CVE-2026-20316Cisco Secure FirewallCisco Secure Firewall Management Center (FMC) Software
11 Aug 2026As of July 2026, Cisco is aware of active exploitation of this vulnerability in the wild and urges immediate patching.
Open advisory
Cisco high security advisory
highPriority 100/100

Cisco

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability

A security flaw exists in Cisco Secure Firewall devices that use the Remote Access SSL VPN service. This flaw lets an attacker who is not logged in send a special message that causes the device to restart unexpectedly, leading to service interruptions. Cisco has released updates that fix this issue, but no temporary solutions are available.

CVE-2026-20349Cisco Secure FirewallCisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCisco Secure Firewall Threat Defense (FTD) Software
11 Aug 2026As of August 2026, Cisco Product Security Incident Response Team (PSIRT) is aware of active exploitation of this vulnerability in the wild. Immediate upgrading is advised.
Open advisory
Cisco high security advisory
highPriority 100/100

Cisco

Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerability

A security flaw in Cisco IOS XE Software's Blocks Extensible Exchange Protocol (BEEP) feature lets attackers cause a device to crash and restart unexpectedly. Attackers do this by sending a specially crafted BEEP SOAP message. This leads to a denial of service (DoS), temporarily disrupting device operation. Cisco has released software updates to fix this issue, and currently, no other ways to avoid this problem exist.

CVE-2026-20263Cisco IOS XE
5 Aug 2026Cisco PSIRT is not aware of any public announcements or exploit activity targeting this vulnerability at this time.
Open advisory
Cisco high security advisory
highPriority 100/100

Cisco

Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability

A security flaw in Cisco IOS and IOS XE software's Extensible Messaging Client Protocol (XMCP) lets attackers remotely crash affected devices. This happens when attackers send malformed XMCP packets, causing the device to unexpectedly reload and become unavailable. The attacker does not need special access or usernames to cause this issue. Cisco has released software updates to fix the problem. There are no workarounds, but a mitigation involving access control lists can limit which clients can connect, reducing risk.

CVE-2026-20301Cisco IOS XE
5 Aug 2026Cisco is not aware of any public announcements or observed malicious exploitation of this vulnerability at this time.
Open advisory
Cisco high security advisory
highPriority 100/100

Cisco

Cisco IOS XE Software SNMP Denial of Service Vulnerability

A security flaw in Cisco IOS XE software's SNMP system can let someone with login access crash the device remotely, causing it to restart unexpectedly and disrupt service. This happens because the software doesn't correctly handle certain bad SNMP messages. An attacker could trigger this by sending a malformed SNMP request if they have valid SNMP credentials. Cisco has released updates to fix this problem. There are no simple workarounds, but administrators can apply a mitigation to reduce the risk.

CVE-2026-20124Cisco IOS XE
5 Aug 2026Cisco PSIRT is not aware of any public announcements or reports of this vulnerability being exploited maliciously in the wild.
Open advisory
Cisco critical security advisory
criticalPriority 100/100

Cisco

Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

A security flaw in Cisco Secure Firewall Management Center (FMC) software lets attackers remotely bypass login controls and run harmful scripts. This could let them take full control over the system behind the firewall. The issue exists because a system process starts incorrectly when the device boots. Attackers can exploit it by sending specially crafted web requests to the device. If your firewall management interface isn’t accessible from the internet, the risk is lower. Cisco has released updates to fix this problem, but there are no other workarounds.

CVE-2026-20079Cisco Secure FirewallCisco Secure Firewall Management Center SoftwareCisco Security Cloud Control Firewall Management
3 Aug 2026Cisco PSIRT is not aware of any public reports or malicious exploitation of this vulnerability at this time.
Open advisory
Cisco high security advisory
highPriority 94/100

Cisco

Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability

Cisco has confirmed a high-severity vulnerability in the command-line interface of three Catalyst SD-WAN control components. A local attacker who already has netadmin privileges can upload a specially crafted file and gain root control of the affected system. Cisco became aware of exploitation in June 2026 and observed limited cases in which configuration changes were pushed to edge devices. Customers should preserve evidence before upgrading, install a fixed release as soon as possible, and check systems and edge-device configurations for compromise.

CVE-2026-20182CVE-2026-20127CVE-2026-20245Cisco
21 Jul 2026Cisco PSIRT became aware of exploitation in June 2026. Exploitation requires netadmin privileges obtained through valid credentials or potentially through CVE-2026-20182 or CVE-2026-20127. Cisco is not aware of successful exploitation by other methods. Limited cases resulted in configuration changes pushed to edge devices.
Open advisory
Fortinet high security advisory
highPriority 87/100

Fortinet

Fortinet FortiOS CAPWAP Out-of-Bounds Write Vulnerability

Fortinet has fixed a high-severity FortiOS vulnerability in the CAPWAP daemon. In practical terms, an attacker who already controls an authenticated FortiAP, FortiExtender, or FortiSwitch could use that trusted device relationship to gain execution privileges on the connected FortiGate. Internet-wide unauthenticated exploitation is not the scenario described by Fortinet, but environments with managed extension devices should verify versions and trust relationships promptly.

CVE-2025-53844FortiGateFortiOSFortiAP
12 May 2026Fortinet reports Known Exploited: No as of the May 12, 2026 advisory. Exploitation requires an attacker to control an authenticated FortiAP, FortiExtender, or FortiSwitch.
Open advisory
Palo Alto Networks medium security advisory
mediumPriority 82/100

Palo Alto Networks

CVE-2026-0298 GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP) (Severity: MEDIUM)

A security flaw in the Windows version of Palo Alto Networks' GlobalProtect app allows attackers who can intercept network traffic to run harmful software on your computer before you log in. This problem only affects Windows devices using a specific login setup called SAML authentication with the Connect Before Logon feature. Other platforms like Linux, macOS, iOS, Android, and Chrome OS are safe. Palo Alto has fixed this in newer app versions and suggests either updating or changing login methods to avoid the risk.

CVE-2026-0298GlobalProtect
12 Aug 2026Palo Alto Networks is not aware of any active exploitation of this vulnerability in the wild.
Open advisory
Cisco medium security advisory
mediumPriority 82/100

Cisco

Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability

A security flaw in the Cisco Catalyst SD-WAN Manager's web interface lets someone with basic login access see sensitive information in plain text, like passwords, by viewing certain logs. This problem happens because the system doesn’t properly restrict access to some types of templates that should be encrypted. Attackers could use these leaked details to take over parts of the network. Cisco has released software updates that fix this issue, but there are no temporary workarounds.

CVE-2026-20294CiscoCisco Catalyst SD-WAN Manager
7 Aug 2026Cisco PSIRT is not aware of any active exploits or public announcements regarding this vulnerability.
Open advisory
Cisco medium security advisory
mediumPriority 82/100

Cisco

Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability

A flaw in Cisco IOS XE's web management system lets a remote user with low access rights cause the device to restart unexpectedly, resulting in downtime. This happens because the system incorrectly handles errors when verifying certificates. There's no temporary fix, but Cisco has issued software updates to resolve this issue.

CVE-2026-20311Cisco IOS XE
5 Aug 2026Cisco Product Security Incident Response Team is not aware of any public exploits or malicious use of this vulnerability at this time.
Open advisory
Cisco medium security advisory
mediumPriority 82/100

Cisco

Cisco Integrated Management Controller Cross-Site Scripting Vulnerability

A weakness in the web interface of Cisco Integrated Management Controller (IMC) allows an attacker who is logged in remotely to trick another user into clicking a harmful link. This can let the attacker run malicious scripts in the user's web browser or steal sensitive information.

CVE-2026-20198CiscoCisco 5000 Series ENCSCatalyst 8300 Series Edge uCPE
5 Aug 2026Cisco PSIRT is not aware of any public exploitation or announcements of this vulnerability at the time of the advisory release.
Open advisory
Cisco medium security advisory
mediumPriority 82/100

Cisco

Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities

Cisco Identity Services Engine (ISE) contains two stored cross-site scripting vulnerabilities in its guest-portal management interface. An attacker with valid administrative credentials could place malicious script code into specific interface pages. The code could then run in another user's browser within the affected interface, potentially exposing sensitive browser-based information. Cisco rates the advisory Medium with a CVSS 3.1 base score of 4.8.

CVE-2025-20204CVE-2025-20205Cisco Identity Services EngineCisco Identity Services Engine (ISE) when guest portals are configured
20 Jul 2026Cisco PSIRT is not aware of public announcements or malicious use of these vulnerabilities.
Open advisory
Palo Alto Networks medium security advisory
mediumPriority 76/100

Palo Alto Networks

CVE-2026-0295 GlobalProtect App: Local Privilege Escalation via Race Condition on macOS (Severity: MEDIUM)

A security flaw in the GlobalProtect app on macOS lets a low-level user gain full administrative access. This means someone with basic access to your Mac could potentially take control of the system. The issue is due to a timing problem in the software that can be exploited locally without needing another person's help.

CVE-2026-0295GlobalProtect
12 Aug 2026Palo Alto Networks is not aware of any malicious exploitation of this vulnerability at this time.
Open advisory
Palo Alto Networks medium security advisory
mediumPriority 76/100

Palo Alto Networks

CVE-2026-0297 GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake (Severity: MEDIUM)

A security flaw in the Palo Alto Networks GlobalProtect app’s handshake process for UDP tunnels can cause the app to crash or allow attackers to run harmful code on your computer with administrative rights. This could let bad actors interrupt your system or take full control of it. Updating the app to the latest versions fixes the vulnerability. If you cannot update immediately, you can change settings to use safer connection methods or configurations to reduce the risk.

CVE-2026-0297GlobalProtect
12 Aug 2026Palo Alto Networks is not aware of any active malicious exploitation of this vulnerability.
Open advisory
Palo Alto Networks medium security advisory
mediumPriority 76/100

Palo Alto Networks

CVE-2026-0296 GlobalProtect App: Improper Certificate Validation Bypass Vulnerability (Severity: MEDIUM)

A security weakness in the GlobalProtect app from Palo Alto Networks allows attackers who can intercept your internet connection to bypass certificate checks. This means attackers could intercept and tamper with some app communications. However, your main VPN traffic remains secure. The issue does not affect GlobalProtect on iOS, Android, or Chrome OS.

CVE-2026-0296GlobalProtect
12 Aug 2026Palo Alto Networks is not aware of any active malicious exploitation of this vulnerability as of the publication date.
Open advisory
Palo Alto Networks medium security advisory
mediumPriority 76/100

Palo Alto Networks

CVE-2026-0299 GlobalProtect App: Local Privilege Escalation Vulnerabilities (Severity: MEDIUM)

A security flaw in the Palo Alto Networks GlobalProtect application lets local users gain administrative control on Windows, macOS, and Linux systems. This means someone with limited access could take over the device and run commands as an administrator. Devices running GlobalProtect on mobile platforms like iOS and Android are safe from this issue.

CVE-2026-0299GlobalProtect
12 Aug 2026Palo Alto Networks is not aware of any malicious exploitation of this vulnerability at this time.
Open advisory
Cisco medium security advisory
mediumPriority 76/100

Cisco

Cisco RoomOS Logging Subsystem Information Disclosure Vulnerability

A flaw in Cisco RoomOS's logging system can let someone with local access and low-level privileges see sensitive data, like login details, by turning on detailed logging and reading the logs. Cisco has fixed this issue with software updates. There are no ways to work around the problem without updating the software.

CVE-2026-20289CiscoCisco RoomOS
5 Aug 2026Cisco PSIRT is not aware of any public exploitation or malicious use of this vulnerability at this time.
Open advisory
Ubuntu unrated security advisory
unratedPriority 76/100

Ubuntu

USN-8620-4: Linux kernel (Intel IoTG) vulnerabilities

Several security vulnerabilities were found in the Linux kernel used by Ubuntu, including issues that could allow attackers to access sensitive information or escalate their privileges. One notable vulnerability in the NTFS file system could let attackers expose kernel memory by using a specially crafted malicious NTFS image. Other vulnerabilities involve certain AMD processors, where attackers with local access might leak sensitive data or gain higher-level access. This update addresses various flaws across many Linux kernel subsystems to enhance system security.

CVE-2023-45896CVE-2025-54505CVE-2025-54518CVE-2022-49803
31 Jul 2026The advisory does not specify whether these vulnerabilities are currently exploited in the wild.
Open advisory
Ubuntu unrated security advisory
unratedPriority 76/100

Ubuntu

USN-8620-3: Linux kernel (Intel IoTG) vulnerabilities

This Ubuntu security advisory reports multiple vulnerabilities found in the Linux kernel, particularly for systems using Intel IoT and AMD processors, as well as various architectures and drivers. One notable issue in the NTFS file system code could let an attacker create a crafted file system image that reveals sensitive kernel memory when mounted. Other vulnerabilities affect AMD processors, potentially allowing local attackers to access sensitive information or escalate privileges. The update addresses numerous flaws across many subsystems and drivers, improving overall system security.

CVE-2023-45896CVE-2025-54505CVE-2025-54518CVE-2022-49803
31 Jul 2026The advisory does not provide information about the current exploitation status of these vulnerabilities.
Open advisory
Ubuntu unrated security advisory
unratedPriority 76/100

Ubuntu

USN-8620-2: Linux kernel (Azure FIPS) vulnerabilities

Ubuntu issued a security update for the Azure FIPS Linux kernel on Ubuntu 22.04 LTS. The update addresses many kernel flaws. Specifically described risks include disclosure of kernel memory through a malicious NTFS image, local disclosure of sensitive processor data on some AMD CPUs, and possible local privilege escalation on some AMD Zen 2 CPUs.

CVE-2023-45896CVE-2025-54505CVE-2025-54518CVE-2022-49803
29 Jul 2026The official notice does not state whether any of these vulnerabilities are being exploited in the wild.
Open advisory
Ubuntu unrated security advisory
unratedPriority 76/100

Ubuntu

USN-8620-1: Linux kernel vulnerabilities

Multiple security vulnerabilities were found in the Linux kernel used by Ubuntu, including problems with the NTFS file system and certain AMD processors that could expose sensitive information or allow attackers to gain higher privileges on the system. These issues affect many parts of the kernel and various drivers, potentially allowing attackers to compromise the system. Updates have been provided to address these problems.

CVE-2023-45896CVE-2025-54505CVE-2025-54518CVE-2022-49803
28 Jul 2026The advisory does not specify whether these vulnerabilities are actively exploited.
Open advisory
Ubuntu unrated security advisory
unratedPriority 76/100

Ubuntu

USN-8619-1: Linux kernel (HWE) vulnerabilities

A number of security vulnerabilities were found in the Linux kernel used in Ubuntu. Some AMD processors had weaknesses that could let a local attacker access sensitive data, escalate privileges, or affect randomness used by security features. Additionally, many other issues affecting various hardware architectures, device drivers, and kernel subsystems were identified that could allow attackers to compromise the system. Ubuntu has provided updates to address these concerns, and users are recommended to update and reboot their systems to apply the fixes.

CVE-2025-54505CVE-2025-54518CVE-2025-62626CVE-2025-21709
28 Jul 2026The source does not specify if any of these vulnerabilities have been exploited in the wild.
Open advisory
Cisco unrated security advisory
unratedPriority 70/100

Cisco

Cisco Advance Notification for Publication of August 19, 2026, Security Advisories

Cisco will publish security advisories on August 19, 2026, revealing details about vulnerabilities in several Cisco products. These advisories will include software updates that fix the security issues. Cisco recommends customers update their software to fully protect their systems.

CiscoBroadWorksCrossworkIndustrial Ethernet 1000 Series Switches
14 Aug 2026The advisory does not specify whether these vulnerabilities have been exploited in the wild.
Open advisory
Ubuntu unrated security advisory
unratedPriority 70/100

Ubuntu

USN-8631-3: Linux kernel (NVIDIA Tegra IGX) vulnerabilities

Researchers found multiple security problems in the Linux kernel used by Ubuntu, including a flaw in WiFi that could let nearby attackers inject harmful packets. These issues affect many parts of the system and could allow attackers to compromise computers. Ubuntu released updates to fix these problems. Users should update and reboot their systems to protect against possible attacks.

CVE-2020-24588CVE-2025-27558CVE-2026-31414CVE-2026-31448
13 Aug 2026The advisory does not specify whether any of these vulnerabilities are actively exploited in the wild.
Open advisory
Ubuntu unrated security advisory
unratedPriority 70/100

Ubuntu

USN-8633-2: Linux kernel vulnerabilities

A security problem was found in the Linux kernel's WiFi system that lets nearby attackers insert fake network packets. This issue arose because a previous fix did not work correctly. Additionally, many other security flaws were found in the Linux kernel that attackers could exploit to compromise systems running Ubuntu. These problems affect many parts of the Linux system. Ubuntu has released updates to fix these flaws. Users should update and reboot their systems to protect against possible attacks.

CVE-2020-24588CVE-2025-27558CVE-2021-47354CVE-2021-47378
13 Aug 2026The advisory indicates that a physically proximate attacker could exploit the WiFi mesh network vulnerability (CVE-2025-27558) to inject packets. It states that multiple security issues could possibly allow an attacker to compromise the system. However, the advisory does not provide details on known active exploitation of these vulnerabilities.
Open advisory
Ubuntu unrated security advisory
unratedPriority 70/100

Ubuntu

USN-8529-2: Linux kernel vulnerabilities

Multiple security vulnerabilities were found in the Linux kernel used by Ubuntu. One key issue, called Fragnesia, involves a logic flaw in a networking subsystem, allowing a local attacker to gain higher privileges or escape container isolation. Various other flaws affect many parts of the kernel, which attackers could exploit to compromise systems. Ubuntu provides updates addressing these issues.

CVE-2026-43503CVE-2021-47202CVE-2024-56643CVE-2026-23272
13 Aug 2026The advisory states that a local attacker could exploit the Fragnesia flaw to escalate privileges or escape containers. Other vulnerabilities could possibly be used by attackers to compromise the system. No definitive exploitation in the wild is stated.
Open advisory
Ubuntu unrated security advisory
unratedPriority 70/100

Ubuntu

USN-8548-2: Linux kernel vulnerabilities

A flaw called Fragnesia was found in the Linux kernel's network security handling, allowing a local attacker to gain higher system access or break out of a container. Additionally, multiple other security issues affecting various parts of the Linux kernel were discovered, potentially allowing attackers to compromise the system. Ubuntu has released updates fixing these issues.

CVE-2026-43503CVE-2021-47117CVE-2021-47202CVE-2023-52646
13 Aug 2026The advisory states that a local attacker could exploit the Fragnesia flaw to escalate privileges or escape a container. It also suggests attackers could use the other vulnerabilities to compromise the system, implying potential exploitable conditions but does not specify whether exploitation is active in the wild.
Open advisory
Ubuntu unrated security advisory
unratedPriority 70/100

Ubuntu

USN-8530-2: Linux kernel (HWE) vulnerabilities

A security issue was found in the Linux kernel used by Ubuntu systems, where the kernel did not handle certain shared memory fragments correctly during network operations. This problem, called Dirty Frag and related to two specific parts (XFRM ESP-in-TCP and RxRPC subsystems), could let a local attacker gain higher access privileges or escape from a container environment. Another similar flaw, called Fragnesia, also affects the XFRM ESP-in-TCP subsystem and poses the same risks. Additionally, several other vulnerabilities were found in various Linux kernel components, which might allow attackers to compromise the system.

CVE-2026-43284CVE-2026-43503CVE-2021-47202CVE-2024-56643
13 Aug 2026The advisory states that a local attacker could exploit these issues to escalate privileges or escape a container, indicating potential for exploitation, but does not specify confirmed exploitation in the wild.
Open advisory
Ubuntu unrated security advisory
unratedPriority 70/100

Ubuntu

USN-8638-1: Axios vulnerabilities

Axios, a popular tool used to send web requests, has several security weaknesses. Attackers could exploit these flaws to bypass proxy restrictions, access internal services they shouldn't, inject harmful data into web requests, or change application responses to gain unauthorized access.

CVE-2025-62718CVE-2026-40175CVE-2026-42043CVE-2026-42044
13 Aug 2026The official source does not specify any information regarding active exploitation of these vulnerabilities.
Open advisory
Ubuntu unrated security advisory
unratedPriority 70/100

Ubuntu

USN-8637-1: Linux kernel (OEM) vulnerabilities

Multiple security weaknesses were found in the Linux kernel that an attacker might exploit to compromise your system. These issues affect many parts of the kernel, including hardware support and network features. Updating your system with the latest security patches will help protect you from these risks.

CVE-2026-46331CVE-2026-52924CVE-2026-53131CVE-2026-53146
13 Aug 2026The advisory does not mention whether these vulnerabilities are currently being exploited in the wild.
Open advisory
Ubuntu unrated security advisory
unratedPriority 70/100

Ubuntu

USN-8631-2: Linux kernel (Oracle) vulnerabilities

Several vulnerabilities were found in the Linux kernel used in Ubuntu, including a WiFi issue that could let nearby attackers inject data packets. Other weaknesses affect different parts of the system, potentially allowing attackers to compromise it. These problems have been fixed in a new software update. Users should update and restart their systems to stay protected.

CVE-2020-24588CVE-2025-27558CVE-2026-31414CVE-2026-31448
13 Aug 2026The advisory does not specify whether these vulnerabilities are being actively exploited in the wild.
Open advisory
Ubuntu unrated security advisory
unratedPriority 70/100

Ubuntu

USN-8636-1: Linux kernel vulnerabilities

Multiple security vulnerabilities were found in the Linux kernel used by Ubuntu. These weaknesses could let attackers take control of affected systems. The issues affect a wide range of kernel components and drivers, including network and file system elements. Ubuntu has released updates to fix these problems and users should apply them promptly and reboot to protect their systems.

CVE-2026-31405CVE-2026-31414CVE-2026-31501CVE-2026-31589
12 Aug 2026The advisory does not state whether these vulnerabilities are currently being exploited in the wild.
Open advisory
Ubuntu unrated security advisory
unratedPriority 70/100

Ubuntu

USN-8635-1: Linux kernel (Azure) vulnerabilities

Multiple security vulnerabilities were found and fixed in the Linux kernel used by Ubuntu systems running on Microsoft Azure. One issue allows nearby attackers to inject harmful WiFi packets due to a bug in how mesh network frames are handled. Another flaw, called Fragnesia, lets local users gain higher access privileges or escape from restricted environments called containers. Numerous other weaknesses affecting various parts of the kernel could let attackers compromise the system.

CVE-2020-24588CVE-2025-27558CVE-2026-43503CVE-2021-47202
12 Aug 2026The advisory does not indicate whether these vulnerabilities are actively exploited in the wild.
Open advisory
Ubuntu unrated security advisory
unratedPriority 70/100

Ubuntu

USN-8634-1: Linux kernel vulnerabilities

Multiple security weaknesses were found in the Linux kernel, which is the core of the Ubuntu operating system. Attackers could use these vulnerabilities to take control of or harm affected systems. This update fixes problems in many parts of the kernel, including hardware support, network communication, file systems, and encryption. Users should update their systems and reboot to protect themselves.

CVE-2026-31405CVE-2026-31414CVE-2026-31448CVE-2026-31649
12 Aug 2026The advisory does not specify whether these vulnerabilities are currently being exploited in the wild.
Open advisory
Ubuntu unrated security advisory
unratedPriority 70/100

Ubuntu

USN-8633-1: Linux kernel vulnerabilities

Multiple security flaws were found in the Linux kernel used by Ubuntu. One notable bug allows an attacker physically near your device to inject malicious WiFi packets because of a problem in handling certain WiFi frames in mesh networks. Other issues affect various parts of the kernel and could let attackers compromise your system.

CVE-2020-24588CVE-2025-27558CVE-2021-47354CVE-2021-47378
12 Aug 2026The advisory states a physically proximate attacker could exploit the WiFi mesh networking vulnerability to inject packets. For other vulnerabilities, it mentions that an attacker could possibly compromise the system, but does not specify publicly known exploits.
Open advisory
Ubuntu unrated security advisory
unratedPriority 70/100

Ubuntu

USN-8631-1: Linux kernel vulnerabilities

Security researchers found multiple vulnerabilities in the Linux kernel used by Ubuntu. One key problem is with the WiFi code handling certain network frames, allowing nearby attackers to inject harmful packets. Other issues affect various parts of the kernel, which attackers might exploit to harm the system. Ubuntu has released updates to address these problems. Users should update their systems and restart to stay protected.

CVE-2020-24588CVE-2025-27558CVE-2026-31414CVE-2026-31448
12 Aug 2026The advisory states that a physically proximate attacker could exploit the WiFi aggregation flaw to inject packets, implying a potential attack vector exists. No mention of known active exploitation beyond this is provided.
Open advisory
Ubuntu unrated security advisory
unratedPriority 70/100

Ubuntu

USN-8630-1: Linux kernel vulnerabilities

The Linux kernel in Ubuntu contains multiple security vulnerabilities affecting various parts of the system. An attacker could exploit these weaknesses to take control or compromise the system. Ubuntu has released updates to fix these vulnerabilities, and users should update and reboot their systems to protect themselves.

CVE-2026-43083CVE-2026-43197CVE-2026-43198CVE-2026-43465
12 Aug 2026The advisory states attackers could possibly exploit these vulnerabilities, but does not specify if any have been actively exploited in the wild.
Open advisory
Ubuntu unrated security advisory
unratedPriority 70/100

Ubuntu

USN-8629-1: Linux kernel vulnerabilities

Multiple security flaws were found in different parts of the Linux kernel used by Ubuntu. These flaws might let attackers take control of the system. An update has been released to fix problems in several kernel subsystems, including those related to CPU architecture, network drivers, and protocols. Users should update their systems and reboot to apply these fixes.

CVE-2026-46331CVE-2026-52924CVE-2026-53131CVE-2026-53151
12 Aug 2026The advisory does not specify whether these vulnerabilities have been exploited in the wild.
Open advisory
Cisco unrated security advisory
unratedPriority 70/100

Cisco

Cisco Advance Notification for Publication of August 5, 2026, Security Advisories

On August 5, 2026, Cisco announced multiple security advisories for various products including Cisco IOS XE and Cisco Catalyst SD-WAN. These advisories cover significant security vulnerabilities such as critical, high, and medium severity issues that could affect device security. Cisco recommends upgrading to the fixed software versions detailed in the advisories to fully address these vulnerabilities. No workarounds are available at this time.

CVE-2026-20303CVE-2026-20304CVE-2026-20310CVE-2026-20312
5 Aug 2026The advisory does not indicate current exploitation in the wild or active attacks leveraging these vulnerabilities.
Open advisory
Ubuntu unrated security advisory
unratedPriority 70/100

Ubuntu

USN-8615-2: Linux kernel (Raspberry Pi) vulnerabilities

Ubuntu says several Linux kernel issues were fixed in the Raspberry Pi kernel packages. One of the issues, called Fragnesia, could let a local attacker gain higher privileges or possibly escape a container. The notice is dated 29 July 2026 and the listed fixes apply to Ubuntu 20.04 LTS and 18.04 LTS Raspberry Pi kernel packages.

CVE-2026-43503CVE-2026-23272CVE-2026-23455CVE-2026-31402
29 Jul 2026The notice describes possible local exploitation for CVE-2026-43503 and says the other issues could possibly be used to compromise the system. It does not state that exploitation in the wild is known.
Open advisory
Palo Alto Networks low security advisory
lowPriority 56/100

Palo Alto Networks

CVE-2026-0301 PAN-OS: Information Disclosure Vulnerability in URL Filtering (Severity: LOW)

A security vulnerability in Palo Alto Networks' PAN-OS software can leak sensitive information in the URL filtering feature. This issue affects firewalls using customized response pages for URL filtering, allowing network attackers without login credentials to access confidential data. Palo Alto Networks has released updated software versions to address the problem and offers mitigation advice for users with customized pages.

CVE-2026-0301PAN-OS
12 Aug 2026Palo Alto Networks is not aware of any malicious exploitation of this vulnerability at this time.
Open advisory